How to Configure Huawei WS5200 Routers Using TR069
Today I’m going to show you how to configure your CPE WS5200 using Made4Graph’s TR-069. I recommend that this be done at a workstation using a public IP address, since it will need to be approved. To do this, we’ll update some information in your CPE using the TR-069 form; we don’t want a customer to be left without internet service. Before beginning the configuration, it is essential that there be no “NAT” of any kind on the network between the CPE and the TR-069 server; if there is, it will compromise TR-069 functionality, as stated in the protocol documentation. Now that I’ve completed the prerequisites, let’s set up the CPE. When you access the CPE, go to the More Functionstab, then System Settings, and TR-069 When you reach the screen shown below, we will make the following settings CWMP Settings: → The TR069 Management button must be enabled→ The Information Interval button must be enabled→ ACS server address = http://ip_do_server_de_tr:7547→ ACS username = admin→ ACS password = admin→ Connection request username = admin→ Connection request password = admin→ Data interval = 300 Then click Save Shortly thereafter, the CPE should appear on made4graph, where it will be approved by our team Some information has been redacted to keep CPE data confidential. If you still have questions, send us a message, and we’ll help you with your CPE.
The importance of a provider having its own DNS
A provider always seeks to provide the best quality internet for its customers, and a very important factor for us to be able to browse the internet is to have a recursive DNS server configured, the reason for this and how it works we already understand, but how to have a server within your network will improve navigation for your customers even more?
How to Configure Archer-C20 Routers Using TR069
Today I’m going to show you how to set up your Archer-C20 on Made4Graph’s TR-069.I recommend doing this in a lab environment with a public IP address, since you’ll need to validate the configuration. To do this, we’ll change some settings on your CPE via TR-069, and we don’t want a customer to be left without internet access.Before starting the configuration, it is essential that there be no “NAT” of any kind on the network between the CPE and the TR-069 server; if there is, it will compromise the functionality of TR-069, according to the protocol documentation.Now that I’ve covered the prerequisites, let’s configure the CPE. When you open CPE, go to the Advanced tab, then System Tools, and finally Settings.When you reach the screen shown below, make the following settings: CWMP Settings:→ The CWMP button must be enabled→ The information button should be active→ Data interval = 300→ ACS URL = http://ip_do_server_de_tr:7547→ ACS username = admin→ ACS password = admin→ Interface used by TR-069 = Any WAN→ CPE ID = SN→ “View SOAP Message” button = disabled→ The “Connection Request Authentication” checkbox must be checkedIn the fields below the connection request box, you will be asked for a username and password; you should enter:→ User = admin→ Password = admin→ Path = /tr069→ Port = 7547 The “Simple UDP Traversal over NATs” option can be enabled, but it does not need to be configured; the settings can be left at their defaults.After that, click Save. Shortly thereafter, the CPE should appear in Made4Graph, where it will be approved by our team Some information has been redacted to keep CPE data confidential.If you still have questions, send us a message, and we’ll help you with your CPE.
Updates – Made4Graph and Made4Flow 04/23
Today, April 11, we released version 2.3.3 of Made4Graph and version 2.0.2 of Made4Flow V2. Here are the main features of this new version: Made4Graph – Version 2.3.3 (April 11, 2023)Added-Added some images from NAS and TR-069 manufacturers by default.-Completely revised the English and Spanish translations.-Added the ability to manage the DMZ in TR-069 for compatible routers.Modified-Changed the traceroute behavior when it does not reach the destination; added hops marked with * and a failure message.-Changed Latin American countries to be prioritized in the phone field in the made4graph demo.-Changed the “new” label in the release notes.-Improved the responsiveness of the login screen. Made4Flow V2 – Version 2.0.2 (April 11, 2023)Added– Added the “start” variable to the Telegram anomaly alert template.Updated– Updated the redirect for the “Click here” link on the demo leads screenFixed– Fixed the dates on the edit screens.– Fixed the duplicate prefix on the “Import prefixes via WHOIS” button. Links to public wikis: https://wiki.made4it.com.br/pt-br/notas_da_versao/made4graphhttps://wiki.made4it.com.br/pt-br/notas_da_versao/made4flow_v2 Demos:https://demo.made4flow.com.br/demohttps://demo.made4graph.com.br/demo
Social Action – Edhucca
Made4it, a technology company based in Apucarana, Paraná, recently carried out a social initiative in partnership with the Paraná Information Technology Industry Union (TI Parana), Apucarana ICT Governance, ACIA, Conecta, and APL de TIC Londrina to assist the NGO Edhucca, also based in Apucarana, Paraná. The initiative involved the donation of 30 computers by TI Parana, which were delivered to the organization. Edhucca is a nongovernmental organization that has been active for over 20 years in the city of Apucarana, Paraná, with the goal of promoting social inclusion and developing professional skills among socially vulnerable youth and adults. With this donation, Edhucca will be able to expand its offerings of courses and training programs, benefiting even more people seeking opportunities. The Dev + Infrastructure course, which will be offered by Edhucca with the help of the donated computers, aims to train students to work in the field of information technology, specifically in software development and systems infrastructure management. This initiative is essential for digital inclusion and for training qualified professionals in a field that is constantly growing. Made4it, for its part, reinforces its commitment to social responsibility and sustainability by promoting an initiative that directly benefits the local community. The company believes that technology can be a powerful tool for transforming lives and fostering social and economic development in the regions where it operates.
Internet service providers face a new wave of DDoS attacks
A lack of care in maintaining equipment, services, and IP address block configurations has put ISPs at imminent risk of distributed denial-of-service attacks Internet service providers (ISPs) are at imminent risk of large-scale distributed denial-of-service (DDoS) attacks, largely due to a lack of care in managing equipment, services, and the configuration of IP address blocks. Last year, several Brazilian ISPs faced difficult times as they dealt with DDoS attacks on their infrastructure, a situation that led to numerous posts on social media, as well as coverage in newspapers and on TV shows. Recently, in late February, a new wave of attacks once again hit several ISPs, with numerous reports involving providers in Rio de Janeiro, some of whom have even spoken out publicly, informing customers that they are facing serious problems in providing services due to these attacks. The victim is not necessarily the target Despite the disruptions they cause to internet service operations, DDoS attacks targeting ISPs—contrary to popular belief—do not necessarily target the ISPs themselves. In most cases, the goal of hacker groups is to use these companies’ infrastructure to attack their actual targets, which are usually large multinational corporations. Equipment with inadequate or incorrect configurations, along with human error, are typically factors that facilitate the exploitation and “recruitment” of this infrastructure into the criminal underworld. During large-scale DDoS attacks, victims are typically hit with a high volume of requests originating from thousands—and sometimes tens of thousands—of different sources, usually spread across the globe. Mitigation measures and strategies that rely on human effort to identify the sources of attacks become ineffective in the face of hackers’ enormous firepower, since these attacks originate from thousands of different malicious sources that suddenly flood the victim’s infrastructure. That is why it is best to rely on an Anti-DDoS system. DDoS attacks spread across 181 countries On the 12th of last month, about two weeks before the new wave of DDoS attacks was made public, Hacknet, an artificial neural network designed to identify hacking activity worldwide, identified and mapped a large network of more than 40,000 servers, spread across 181 countries, that were being used to launch DDoS attacks. The news was posted on the website and social media accounts of NetSensor, the company that maintains this neural network, along with a link to download the list of IP addresses being used in the attacks, so that security professionals could take preventive measures to protect themselves. NetSensor reviewed the list of devices that were being exploited, enriched it with additional data, and sent private notifications to the email addresses registered as the contact information for each IP address block. In Brazil, more than 1,000 companies were involved, resulting in more than 1,600 contact emails, in which NetSensor issued the alert, provided information about the device, and made itself available to answer any further questions. The results of the notifications were a negative surprise, with things like: The saddest response came from the person in charge of a provider’s server, who simply wrote: “Please remove my email from the list.” Few companies take this seriously There were also some companies that responded positively to the alert. Some forwarded the case to the person in charge of the device using that IP address; others requested more information about the case; and still others thanked us for the alert and said they would review the case and take the necessary measures. Unfortunately, the percentage of companies that took this more serious and professional approach was around 0.5%. Given this scenario, companies in general need to keep in mind that cybercrime has become much more sophisticated in recent years; it has become highly organized, structured, intelligent, and profitable. Therefore, to be able to confront and defend against these cybercriminals, we must develop techniques and knowledge and make intelligent use of resources that match the level of our attackers. In other words, we must seek out new approaches and technologies capable of helping us defend against emerging threats—threats that we are currently unable to address effectively. Furthermore, the neglect, incompetence, and negligence we see in relation to networks, equipment, and services can no longer be tolerated. Only then will we have a chance of success in confronting the threats that surround us, coming from the dark side of the internet. Source: https://www.cisoadvisor.com.br/provedores-de-internet-enfrentam-nova-onda-de-ataques-ddos/ How to Protect Your Internet Service Provider from DDoS Attacks Just as there are tools used by attackers, we also have tools and methods to protect the service provider. What we need to do is mitigate the attack, which involves protecting the target from DDoS attacks. Made4it has the right tool for you: Made4Flow!With Made4Flow, you can detect attacks and take action to protect your provider. Learn about the benefits of anti-DDoS for internet service providers:
What’s new in Zabbix 6.4?
The new release focuses on simplifying Zabbix configuration, allowing Zabbix to instantly propagate configuration changes across large, distributed environments, as well as streamlining software update workflows. Organizations using LDAP or SAML will benefit from the new Just-in-time (JIT) user provisioning capabilities, allowing IT administrators to propagate Zabbix users using centralized user authentication mechanisms. This update also contains several templates and integrations for the most popular vendors and cloud providers such as Veeam, AWS, Azure, Cisco and many others. Just-in-time (JIT) user provisioning Automatically create and update your Zabbix users with the new Just-in-time user provisioning feature for LDAP and SAML: Cause and symptoms events To allow for an overview of issues and better filtering options, as well as identifying root cause of issues, issue events can now be marked as cause or symptom events: Instant propagation of configuration changes Instantly sync your configuration changes to Zabbix Agent and Proxy, running in active or passive modes. Zabbix active and passive proxies can now capture any configuration changes made to your Zabbix instance almost instantly: The active Zabbix agent now receives a complete copy of configuration only when configuration changes are made between configuration synchronization intervals: Zabbix update without downtime To improve Zabbix component update flows (especially for large environments), proxies are now backward compatible within the same LTS release cycle: Speed and performance improvements to bulk SNMP discovery and data collection A new way to collect a large amount of SNMP metrics in bulk with minimal performance impact on the monitored endpoint using GetBulk requests: New menu layout The Zabbix menu layout has been redesigned. The purpose of the new menu layout is to provide logical and consistent access to key Zabbix features: Real-time streaming of HTTP metrics and events Transmit real-time metrics and events from Zabbix to external systems via HTTP: Template Versioning Template versioning was introduced to improve template management and make it easier: Development framework for creating Zabbix widgets Several design changes have been made with the aim of simplifying the workflow for creating custom widgets in Zabbix: Optional interfaces for server-originated checks. A host interface is no longer needed for item types related to collections initiated directly from Zabbix Server or Zabbix Proxy: Simplified setup of media types for multiple email service providers Zabbix 6.4 simplifies the workflow of configuring a new email media type by allowing you to select from several pre-configured email service providers: Additional templates and integrations Zabbix 6.4 comes with many new templates for the most popular cloud providers and vendors: Zabbix 6.4 introduces a webhook integration for the Line messaging app, allowing events from Zabbix to be forwarded to the app Additional changes and improvements Made4it is a technology company that is proud to be a certified partner of Zabbix, one of the world’s most renowned network monitoring platforms. As certified partners, our professionals are highly skilled at providing customized solutions tailored to each client’s specific needs. Our network monitoring solutions are comprehensive and range from basic configuration to the implementation of advanced solutions for large-scale networks. With Made4it, you can rest assured that your system is being monitored 24 hours a day, 7 days a week, ensuring the security and optimal performance of your network. In addition, we have a highly qualified support team that is always ready to help if you have any problems or questions. With Made4it, you can rest assured that you’re in good hands. Don’t waste any more time and get to know our network monitoring services. Contact us today and find out how we can help your business perform even better!
GRE + IPSec tunnel between Cisco IOS and Huawei NE40
In this post we will discuss a very common (and little documented) scenario, which is to use a GRE tunnel secured with IPSec between a Cisco IOS ASR1002 router and a Huawei NE40 router. The topology for this example is described below. It has been kept simple so that we can discuss the details of GRE+IPSEC without getting into the rest of the network. In this setup, we have a Cisco router with the public IP address 198.51.100.2 and a Huawei NE40 router with the public IP address 203.0.113.66. Both are connected to the Internet and are connected to each other. We need to establish a GRE tunnel between the routers and secure it using IPSec in tunnel mode. The tunnel’s address space is 172.31.31.0/30. Important License/Module Information Check with the manufacturer of your equipment to see if some kind of service card, or license is not required. In the case of the equipment in this lab, the NE40-M2K router did not need an additional physical module, just the IPSec license. On the Cisco router no license was needed either, because its IOS was already in ADVIPSERVICES-K9 (which contains the entire basis for Ipsec). *Helpful information*: if you want to run IKEv1, on the Huawei router you need a software module for IKEv1 (which you get from the Huawei vendor). Cisco IOS XE Configurations So let’s configure the Cisco router to establish the VPN. I won’t go into detail about the physical interfaces, only about the VPN. At the end of the article there is a block with the relevant conf of them. Phase 1 settings, according to the table above: Everything above applies to Phase 1. So when you’re troubleshooting issues, and the problem is related to this phase, you’ll already know where to look 🙂. Now setting up phase 2: Too simple on Cisco! We will now combine the two phases into one profile: Creating the GRE tunnel and adding IPSec protection: Huawei Settings So let’s configure the Huawei router to establish the VPN. As with Cisco, I won’t go into detail about the physical interfaces, only the VPN. At the end of the article there is a block with the relevant conf of them. The configuration on the Huawei router is a bit more complex, as it creates one tunnel for the GRE protocol, and one tunnel for IPSec. Also, we want to use the same IP for both tunnels, so a VRF is needed. 😮 Creating the service instance to use the VPN (only applicable on NE40): Upgrading the new VRF (vpn-instance): Creating the two Loopback interfaces with the same IP (VRF magic). The looback with the IPSec tunnel will be in the public routing table, while the one with the GRE tunnel will be in the VPNA table. Now we come to IPSec. The interesting traffic ACL defines the traffic that will be protected by IPSec. In this case then, we will have GRE traffic between the IPs of site A and site B. Note that I only communicate in one direction – the direction of the router protecting its traffic). The above ACL can be read like this: “Protect GRE protocol data coming from VRF vpna between source 203.0.113.66 and destination 198.51.100.2” Now let’s move on to setting up Phase 1 (remember that Cisco actually starts with this phase—it’s much simpler). In the middle of this phase, there are some VPN-Instance binding configurations, due to the VRF that was created. Everything above applies to Phase 1. So when you’re troubleshooting issues, and the problem is related to this phase, you’ll already know where to look 🙂. We move on to phase 2: We will now combine the two phases into one profile: Creating GRE and IPSEC tunnels. Let’s not get confused: Tunnel 900 – is a GRE tunnel, operating inside the vpna. Tunnel 10 – is an IPSec tunnel, operating on the global table The idea at Huawei is to have an IPSec tunnel running on the outside and a second GRE tunnel on the inside, with one encapsulated within the other. But the funny thing is that the GRE tunnel runs outside the VRF, and the IPSec tunnel runs inside it. It’s a bit of a mess, isn’t it? Then tunnel900 which is the GRE (and which receives the IPs from /30) uses a destination that goes inside the VPNA. And inside the VPNA the destination is reached by the IPSec tunnel. Also note that the IPsec policy has been associated with tunnel 10, using the profile that was created. Last but not least, a route that is somewhat complex in itself: within the VPNA instance, I specify that to reach the remote peer, I use the newly created IPSec interface, with the peer itself as the next hop. And so we set up the Huawei router. Let’s see if it has gone up now. Operation Validation In the tunnel validation process, we must always remember that each phase and stage depends on the complete establishment of the other, so there is no point in wanting to have connectivity if phase 1 has not yet established communication. On both routers, we will validate in sequence: Let’s go to the tests. Cisco Check Validating connectivity via ICMP ping Checking that IKEv2 has established in Phase 1: When nothing appears in the output, or it is not ready, it means that some of the parameters in Phase 1 did not match. Check on both sides if they agree. We continue validation in Phase 2: In the output above, we see that the routers have switched the “interesting traffic” contract. Each side has committed to protecting one direction of GRE communication. Following on still in Phase 2, there are some very important counters that refer to packets sent/received/encrypted/verified. It is in the output of the “show crypto ipsec sa” command. Let’s take a look at them. When these counters are not incrementing, or still incrementing failures, it is because some Phase 2 configuration is not
Launch Made4Flow v2
We are very proud to announce the release of version 2 of Made4Flow and Anti-DDoS. Bringing several improvements, this version brings new features and optimizations. With a much more attractive look and interactive dashboard customization option, Made4Flow v2 stands out with its much more polished and refined interface, and also much faster and dynamic compared to its predecessor.
What is TR-069 and how it can help providers
TR-069 is a network device management protocol. It allows ISPs to remotely manage and configure network devices such as routers and modems.
With TR-069, ISPs can automate configuration, monitoring, and maintenance tasks for network devices, which helps ensure that Internet services run consistently and efficiently. In addition, TR-069 also allows providers to collect device performance data, which helps them identify and resolve issues quickly and efficiently.
In summary, TR-069 is a valuable tool for Internet Service Providers as it allows you to automate and manage network devices remotely, collect performance data to quickly identify and resolve problems, automate software and firmware upgrades, and offer network management for your customers, which can help reduce costs, increase operational efficiency, and increase customer satisfaction and loyalty.